Viewing France site · Prices in EUR · fr.antimatterav.ca
HighActiveTrending
High Risk
75%

Trojan Loader

Initial-stage malware that downloads and executes secondary payloads.

#malware#loader#dropper

Threat Overview

Loaders such as Emotet-style droppers and malvertising chains deliver stealers, ransomware, and remote access tools in staged infections.

Attack Behavior

  • Downloads encrypted second-stage payloads
  • Establishes persistence via scheduled tasks
  • Disables security tools when possible

Infection Methods

  • Macro-enabled documents
  • Cracked software bundles
  • Drive-by downloads

Symptoms & Indicators

  • New scheduled tasks
  • Unexpected outbound connections
  • Subsequent infostealer or ransomware deployment

Immediate Mitigation

  • Block command-and-control domains at firewall
  • Isolate endpoint on detection
  • Collect memory dump for analysis

Removal Guidance

  • Full offline scan in recovery environment
  • Remove persistence keys and tasks
  • Validate system file integrity

Prevention Methods

  • Disable macros from internet origins
  • Block unsigned script execution
  • Real-time behavioral analysis

Telemetry Indicators

  • powershell -enc launches
  • WMI event subscription creation
  • Known loader mutex strings

They are the delivery mechanism for the most damaging follow-on malware including ransomware and APT tooling.

AntiMatter AV — Enterprise Cybersecurity Platform